New Registrations

Venmo phishing domains

Newly registered lookalikes - tracked daily


Venmo phishing domains

Newly registered lookalikes - tracked daily


Tracked (7d)
3
New (24h)
0
vs avg
Website
venmo.com
About
AIP2P payments target (US). Same lure pattern as Cash App - fake 'fraud alert' or 'pending payment' notifications harvesting credentials and the linked bank-card balance.
TLDs
.com (3)
Countries
United StatesUnited States (1) · SingaporeSingapore (1)

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) URL Screenshot Flags Details
2026-06-07 02:58 2026-06-07 02:58
https://venmoserver-pay.com
Screenshot of venmoserver-pay.com Details
2026-06-06 04:11 2026-06-06 04:11
https://venmo-send.com
Screenshot of venmo-send.com Details
2026-06-04 03:10 2026-06-04 03:10
https://venmopay-online.com
Screenshot of venmopay-online.com Details

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

URL Screenshot Details
https://venmoserver-pay.com
Screenshot of venmoserver-pay.com Details
https://venmo-send.com
Screenshot of venmo-send.com Details
https://venmopay-online.com
Screenshot of venmopay-online.com Details

AIHow to verify a real Venmo URL

  • Legitimate Venmo URLs always end in venmo.com (e.g. www.venmo.com, account.venmo.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not Venmo.
  • The domains listed above were registered within the last 7 days. New-domain age is itself a signal — Venmo has owned venmo.com for years; brand-new look-alikes are almost never legitimate.
  • If you got the link from email, SMS, or social media, do not click it. Open venmo.com from your browser bookmark or type the domain manually.
  • Real Venmo pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.